Bug 1577319 (CVE-2018-10780) - CVE-2018-10780 exiv2: heap-based buffer over-read in Exiv2::Image::byteSwap2 function in image.cpp
Summary: CVE-2018-10780 exiv2: heap-based buffer over-read in Exiv2::Image::byteSwap2 ...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2018-10780
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1577320 1577321
Blocks: 1577323
TreeView+ depends on / blocked
 
Reported: 2018-05-11 17:29 UTC by Laura Pardo
Modified: 2020-02-11 00:43 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-05-29 18:02:22 UTC


Attachments (Terms of Use)

Description Laura Pardo 2018-05-11 17:29:43 UTC
A flaw was found in Exiv2 0.26, function Exiv2::Image::byteSwap2 in image.cpp file has a heap-based buffer over-read. This allows attackers to cause a denial of service attack.


References:
https://bugzilla.redhat.com/show_bug.cgi?id=1575201

Comment 1 Laura Pardo 2018-05-11 17:30:06 UTC
Created exiv2 tracking bugs for this issue:

Affects: fedora-all [bug 1577321]

Comment 4 Pedro Yóssis Silva Barbosa 2018-05-29 18:02:22 UTC
Closing as NOTABUG. 
The POC doesn't reach the byteSwap2 function. The reporter said that the POC was for Ubuntu 16.04, not RHEL.


Note You need to log in before you can comment on or make changes to this bug.